├── .gitignore ├── LICENSE ├── Readme.md ├── pom.xml ├── shiroattack.iml └── src └── main └── java └── com └── govuln └── shiroattack ├── Client.java ├── Client0.java ├── Client1.java ├── CommonsBeanutils1Shiro.java ├── CommonsCollections6.java ├── CommonsCollectionsShiro.java ├── Evil.java ├── Main.java ├── asm ├── Resolver.java ├── ShortClassVisitor.java └── ShortMethodAdapter.java └── memshell ├── BehinderFilter.java ├── BehinderFilterSpring.java ├── BehinderFilter_all.java ├── ClassDataLoader.java ├── Client_memshell.java ├── Client_memshell_spring.java ├── Client_memshell_tomcat.java ├── InjectToFilter.java ├── MyClassLoader.java ├── TomcatFilter.jsp └── shell.jsp /.gitignore: -------------------------------------------------------------------------------- 1 | # Project exclude paths 2 | /target/ 3 | .idea 4 | -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/LICENSE -------------------------------------------------------------------------------- /Readme.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/Readme.md -------------------------------------------------------------------------------- /pom.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/pom.xml -------------------------------------------------------------------------------- /shiroattack.iml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/shiroattack.iml -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/Client.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/Client.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/Client0.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/Client0.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/Client1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/Client1.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/CommonsBeanutils1Shiro.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/CommonsBeanutils1Shiro.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/CommonsCollections6.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/CommonsCollections6.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/CommonsCollectionsShiro.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/CommonsCollectionsShiro.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/Evil.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/Evil.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/Main.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/Main.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/asm/Resolver.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/asm/Resolver.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/asm/ShortClassVisitor.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/asm/ShortClassVisitor.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/asm/ShortMethodAdapter.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/asm/ShortMethodAdapter.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/BehinderFilter.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/BehinderFilter.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/BehinderFilterSpring.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/BehinderFilterSpring.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/BehinderFilter_all.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/BehinderFilter_all.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/ClassDataLoader.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/ClassDataLoader.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/Client_memshell.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/Client_memshell.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/Client_memshell_spring.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/Client_memshell_spring.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/Client_memshell_tomcat.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/Client_memshell_tomcat.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/InjectToFilter.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/InjectToFilter.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/MyClassLoader.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/MyClassLoader.java -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/TomcatFilter.jsp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/TomcatFilter.jsp -------------------------------------------------------------------------------- /src/main/java/com/govuln/shiroattack/memshell/shell.jsp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/godzeo/shiro_cb_memshell/HEAD/src/main/java/com/govuln/shiroattack/memshell/shell.jsp --------------------------------------------------------------------------------